2023 CVE Vulnerabilities

31,244 CVEs published in 2023.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2023-45387CRITICAL9.8In the module "Product Catalog (CSV, Excel, XML) Export PRO" (exportproducts) in versions up to 5.0.0 from MyPrestaModul...
CVE-2023-48078CRITICAL9.8SQL Injection vulnerability in add.php in Simple CRUD Functionality v1.0 allows attackers to run arbitrary SQL commands ...
CVE-2023-6014CRITICAL9.8An attacker is able to arbitrarily create an account in MLflow bypassing any authentication requirment.
CVE-2023-6019CRITICAL9.8A command injection existed in Ray's cpu_profile URL parameter allowing attackers to execute os commands on the system r...
CVE-2023-6018CRITICAL9.8An attacker can overwrite any file on the server hosting MLflow without any authentication.
CVE-2023-6016CRITICAL9.8An attacker is able to gain remote code execution on a server hosting the H2O dashboard through it's POJO model import f...
CVE-2023-47674CRITICAL9.8Missing authentication for critical function vulnerability in First Corporation's DVRs allows a remote unauthenticated a...
CVE-2023-47213CRITICAL9.8First Corporation's DVRs use a hard-coded password, which may allow a remote unauthenticated attacker to rewrite or obta...
CVE-2023-47003CRITICAL9.8An issue in RedisGraph v.2.12.10 allows an attacker to execute arbitrary code and cause a denial of service via a crafte...
CVE-2023-48365CRITICAL9.9Qlik Sense Enterprise for Windows before August 2023 Patch 2 allows unauthenticated remote code execution, aka QB-21683....
CVE-2023-41442CRITICAL9.8An issue in Kloudq Technologies Limited Tor Equip 1.0, Tor Loco Mini 1.0 through 3.1 allows a remote attacker to execute...
CVE-2023-48224CRITICAL9.1Fides is an open-source privacy engineering platform for managing the fulfillment of data privacy requests in a runtime ...
CVE-2023-5245CRITICAL9.8FileUtil.extract() enumerates all zip file entries and extracts each file without validating whether file paths in the a...
CVE-2023-47445CRITICAL9.8Pre-School Enrollment version 1.0 is vulnerable to SQL Injection via the username parameter in preschool/admin/ page.
CVE-2023-47678CRITICAL9.1An improper access control vulnerability exists in RT-AC87U all versions. An attacker may read or write files that are n...
CVE-2023-47308CRITICAL9.8In the module "Newsletter Popup PRO with Voucher/Coupon code" (newsletterpop) before version 2.6.1 from Active Design fo...
CVE-2023-43979CRITICAL9.8ETS Soft ybc_blog before v4.4.0 was discovered to contain a SQL injection vulnerability via the component Ybc_blogBlogMo...
CVE-2023-39337CRITICAL9.1A security vulnerability in EPMM Versions 11.10, 11.9 and 11.8 older allows a threat actor with knowledge of an enrolled...
CVE-2023-39335CRITICAL9.8A security vulnerability has been identified in EPMM Versions 11.10, 11.9 and 11.8 and older allowing an unauthenticated...
CVE-2023-45616CRITICAL9.8There is a buffer overflow vulnerability in the underlying AirWave client service that could lead to unauthenticated rem...
CVE-2023-45615CRITICAL9.8There are buffer overflow vulnerabilities in the underlying CLI service that could lead to unauthenticated remote code e...
CVE-2023-45614CRITICAL9.8There are buffer overflow vulnerabilities in the underlying CLI service that could lead to unauthenticated remote code e...
CVE-2023-47130CRITICAL9.8Yii is an open source PHP web framework. yiisoft/yii before version 1.1.29 are vulnerable to Remote Code Execution (RCE)...
CVE-2023-36049CRITICAL9.8.NET, .NET Framework, and Visual Studio Elevation of Privilege Vulnerability
CVE-2023-34060CRITICAL9.8VMware Cloud Director Appliance contains an authentication bypass vulnerability in case VMware Cloud Director Appliance ...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now